SlideShare a Scribd company logo
1 of 19
Oh yes, that Pentium 90 under your desk is running a
business critical app. Time to look at it.
Darren Duke – Technical Deus - STS – June 2013
About me
 AKA my favorite slide
 Started with “Lotus Notes” in R3
 Yes, really….R3
 Founder of STS based in Atlanta
 Sometime blogger, ranting Tweeter, ex-
host of This Week In Lotus, Speaker,
Fixture at “Ask the PM’s”
 I am obnoxious as obnoxiousness is
usually required to elicit answers from IBM
 “Experience is the name one gives to their
mistakes” – Oscar Wilde
Traveler, like BES = top
down
 Your CEO told your boss to make his
iPad work
 Your boss told you to make the CEO’s,
and now also *his* as he needs one “for
support”, iPads work
 You got no budget and an old desktop
server or VM and installed Traveler
 After the first email, this server was
business critical
Now everyone has one
 Once word was out…..
 You became very popular
iOS Devices are for
“work”….
 Hence the executives desire to get them
to work
 But we all know the real reason…
Security Options
 None. Erm….Whiskey Tango Foxtrot?
 SSL on Domino
 SSL on IHS in front of Domino (new in 9)
 Reverse Proxy
 IBM Mobile Connect
 Certificate authentication**
 You can always go back to BES ;)
Traveler is “free”
 Only if you don’t secure it
 How much did your org spend on BES?
 Server, CALs, Devices, Support….
 Why do you not treat your Traveler as
you did you BES?
 Spend money and do it right and secure it
 It’ll still come out cheaper than your BES did
A word about DNS and SSL
 Whatever solution you choose to secure
your Traveler server….
 Make sure DNS and protocol is the same
inside and out
 my_traveler_server.mycomany.com
 If you use SSL on the outside, you must use it
on the inside too
 That means you may use more than one
solution
 Outside LAN : IHS + SSL + Reverse Proxy
 Inside LAN : IHS + SSL
None – aka the default
 As the great Paul Mooney once said:
 “Port 80 on Traveler is *very* unwise”
 Your passwords (and everything else) is
going across the internet in clear text
 But…..
 it scales well - joke
 Still, I would not do this on my servers. Ever.
 Even the installer warns you this is a bad
idea
 Free
 Until you are hacked
SSL on Domino
 Everything is secure if you did it right
 Redirect all traffic from 80 to SSL (443) in the
server doc, ports
 Self Signed SSL can be used
 But cause issues on some (all?) Androids
 You can get around this by side loading or
maybe the via the Google Play store now
 Domino SSL scaling may cause issues
 Domino still “surfaced” on the internet
 Reasonably cheap
SSL on IHS in front of
Domino
 New in 9.0, install IBM HTTP Server (IHS)
 Installed as option with Domino, on same server
as Domino
 Windows only for now, needs 9.0 IF1
○ PMR if you want other OSes to get this
 Will handle SSL
 Fixes Domino scaling with SSL
 “Allows” Domino HTTP to do TLS
 IHS now surface to the internet
 Reasonably cheap
Reverse Proxy
 A proxy (like Websphere Edge Server,
F5 or Apache) in the DMZ forwards
traffic to Traveler in the LAN/DMZ
 Can also be done with IHS, not sure
about the licensing of that
 Domino has no surface on the internet
 Proxy can handle SSL
 Can be cheap, or expensive
IBM Mobile Connect
 IBM’s “headless VPN” solution
 Think of it like a very secure reverse proxy
 Can be used for iNotes, Connections
and Quickr too
 Out of the box (mostly) support for
Traveler
 No messy http.conf or domino.conf files
 Maybe relatively cheap based on current
license you have
IBM Mobile Connect Licensing
 If you have Domino Enterprise Server
licensing
 Full PVU or CEO
 NOT Express
 You get the CAL for IMC as an entitlement
 Will only need to license IMC PVUs
 None enterprise
 You’ll need clients and PVUs
All the previous slides were
server security
 What about users?
 Usually the weakest link
 Options
 Complex internet password
 Internet Password Lockout
 Certificate based authentication
Password Security
 Your weakest link if you install Traveler
correctly
 Complex passwords are good for you
 Suck for your user
 Password changes are difficult to do on
a device
 There is a possible solution…
Go password-less
 Certificate based authentication
 Well, on iOS devices
 Android is on the Traveler road map (PMR it)
 Really a function of the Domino HTTP server
and the device
 This is much easier with an MDM
 Pushing certificates is easier with a MDM
 You have to get the cert on the device
 Make sure users have device
passwords!!!
Conclusion
 You may decide to use multiple methods
 Domino + IHS + IMC + Certificates
 Yes, it can get complex
 Yes, it can be very, very secure
 Almost BES like, but not quite
 You may want to evaluate MDM’s before
attempting a certificate roll out
 Switching from non-SSL to SSL is “difficult”
 A secure, HA Traveler platform can be
expensive to implement
 But hey, so was BES
Q&A and links
 http://blog.darrenduke.net
 Mostly useful stuff, some rants
 http://www.simplified-tech.com
 No rants, Lisa won’t let me
 https://twitter.com/darrenduke
 Mostly rants, some useful stuff
 http://geldreddotcom.files.wordpress.com/2013/05/choosing-a-
mdm-presentation.pdf
 choosing an MDM
 I like DesktopCentral for the record
 Never allow Anonymous access to the Domino Directory…..ever. Never.

More Related Content

More from Lisa Duke

May EFT Welcome.pptx
May EFT Welcome.pptxMay EFT Welcome.pptx
May EFT Welcome.pptxLisa Duke
 
What's Your Financial Operating System?
What's Your Financial Operating System?What's Your Financial Operating System?
What's Your Financial Operating System?Lisa Duke
 
Financial independence for entrepreneurs
Financial independence for entrepreneursFinancial independence for entrepreneurs
Financial independence for entrepreneursLisa Duke
 
How to Start A Side Hustle During Your Job Search
How to Start A Side Hustle During Your Job SearchHow to Start A Side Hustle During Your Job Search
How to Start A Side Hustle During Your Job SearchLisa Duke
 
Mwlug the truth about being an entrepreneur
Mwlug the truth about being an entrepreneurMwlug the truth about being an entrepreneur
Mwlug the truth about being an entrepreneurLisa Duke
 
What The Heck is IBM Smart Cloud
What The Heck is IBM Smart CloudWhat The Heck is IBM Smart Cloud
What The Heck is IBM Smart CloudLisa Duke
 
The Truth About Being an Entrepreneur
The Truth About Being an EntrepreneurThe Truth About Being an Entrepreneur
The Truth About Being an EntrepreneurLisa Duke
 
Introduction to STS
Introduction to STSIntroduction to STS
Introduction to STSLisa Duke
 
MWLUG - If You Build It Will They Come: Driving User Adoption for Social Sof...
MWLUG - If You Build It Will They Come:  Driving User Adoption for Social Sof...MWLUG - If You Build It Will They Come:  Driving User Adoption for Social Sof...
MWLUG - If You Build It Will They Come: Driving User Adoption for Social Sof...Lisa Duke
 
P12035 simplifiedtech-uadeck-sharedeck
P12035 simplifiedtech-uadeck-sharedeckP12035 simplifiedtech-uadeck-sharedeck
P12035 simplifiedtech-uadeck-sharedeckLisa Duke
 
Social Media and Social Business Overview
Social Media and Social Business OverviewSocial Media and Social Business Overview
Social Media and Social Business OverviewLisa Duke
 
St. Louis IAMLUG
St. Louis IAMLUGSt. Louis IAMLUG
St. Louis IAMLUGLisa Duke
 
Lotus live ibm client references
Lotus live ibm client referencesLotus live ibm client references
Lotus live ibm client referencesLisa Duke
 
Quickr: What Is It Good For? Use Cases from STS and Our Clients
Quickr: What Is It Good For?  Use Cases from STS and Our ClientsQuickr: What Is It Good For?  Use Cases from STS and Our Clients
Quickr: What Is It Good For? Use Cases from STS and Our ClientsLisa Duke
 
Sametime Introduction
Sametime IntroductionSametime Introduction
Sametime IntroductionLisa Duke
 
STS Domino Licensing Webinar
STS Domino Licensing WebinarSTS Domino Licensing Webinar
STS Domino Licensing WebinarLisa Duke
 
X Pages On A Shoestring
X Pages On A ShoestringX Pages On A Shoestring
X Pages On A ShoestringLisa Duke
 
How To Start And Grow A User Group
How To Start And Grow A User GroupHow To Start And Grow A User Group
How To Start And Grow A User GroupLisa Duke
 
Quickr Introduction
Quickr IntroductionQuickr Introduction
Quickr IntroductionLisa Duke
 
BES On Domino
BES On DominoBES On Domino
BES On DominoLisa Duke
 

More from Lisa Duke (20)

May EFT Welcome.pptx
May EFT Welcome.pptxMay EFT Welcome.pptx
May EFT Welcome.pptx
 
What's Your Financial Operating System?
What's Your Financial Operating System?What's Your Financial Operating System?
What's Your Financial Operating System?
 
Financial independence for entrepreneurs
Financial independence for entrepreneursFinancial independence for entrepreneurs
Financial independence for entrepreneurs
 
How to Start A Side Hustle During Your Job Search
How to Start A Side Hustle During Your Job SearchHow to Start A Side Hustle During Your Job Search
How to Start A Side Hustle During Your Job Search
 
Mwlug the truth about being an entrepreneur
Mwlug the truth about being an entrepreneurMwlug the truth about being an entrepreneur
Mwlug the truth about being an entrepreneur
 
What The Heck is IBM Smart Cloud
What The Heck is IBM Smart CloudWhat The Heck is IBM Smart Cloud
What The Heck is IBM Smart Cloud
 
The Truth About Being an Entrepreneur
The Truth About Being an EntrepreneurThe Truth About Being an Entrepreneur
The Truth About Being an Entrepreneur
 
Introduction to STS
Introduction to STSIntroduction to STS
Introduction to STS
 
MWLUG - If You Build It Will They Come: Driving User Adoption for Social Sof...
MWLUG - If You Build It Will They Come:  Driving User Adoption for Social Sof...MWLUG - If You Build It Will They Come:  Driving User Adoption for Social Sof...
MWLUG - If You Build It Will They Come: Driving User Adoption for Social Sof...
 
P12035 simplifiedtech-uadeck-sharedeck
P12035 simplifiedtech-uadeck-sharedeckP12035 simplifiedtech-uadeck-sharedeck
P12035 simplifiedtech-uadeck-sharedeck
 
Social Media and Social Business Overview
Social Media and Social Business OverviewSocial Media and Social Business Overview
Social Media and Social Business Overview
 
St. Louis IAMLUG
St. Louis IAMLUGSt. Louis IAMLUG
St. Louis IAMLUG
 
Lotus live ibm client references
Lotus live ibm client referencesLotus live ibm client references
Lotus live ibm client references
 
Quickr: What Is It Good For? Use Cases from STS and Our Clients
Quickr: What Is It Good For?  Use Cases from STS and Our ClientsQuickr: What Is It Good For?  Use Cases from STS and Our Clients
Quickr: What Is It Good For? Use Cases from STS and Our Clients
 
Sametime Introduction
Sametime IntroductionSametime Introduction
Sametime Introduction
 
STS Domino Licensing Webinar
STS Domino Licensing WebinarSTS Domino Licensing Webinar
STS Domino Licensing Webinar
 
X Pages On A Shoestring
X Pages On A ShoestringX Pages On A Shoestring
X Pages On A Shoestring
 
How To Start And Grow A User Group
How To Start And Grow A User GroupHow To Start And Grow A User Group
How To Start And Grow A User Group
 
Quickr Introduction
Quickr IntroductionQuickr Introduction
Quickr Introduction
 
BES On Domino
BES On DominoBES On Domino
BES On Domino
 

Recently uploaded

Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 

Recently uploaded (20)

Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 

I Have a Traveler Server - Maybe I Should Secure It Some?

  • 1. Oh yes, that Pentium 90 under your desk is running a business critical app. Time to look at it. Darren Duke – Technical Deus - STS – June 2013
  • 2. About me  AKA my favorite slide  Started with “Lotus Notes” in R3  Yes, really….R3  Founder of STS based in Atlanta  Sometime blogger, ranting Tweeter, ex- host of This Week In Lotus, Speaker, Fixture at “Ask the PM’s”  I am obnoxious as obnoxiousness is usually required to elicit answers from IBM  “Experience is the name one gives to their mistakes” – Oscar Wilde
  • 3. Traveler, like BES = top down  Your CEO told your boss to make his iPad work  Your boss told you to make the CEO’s, and now also *his* as he needs one “for support”, iPads work  You got no budget and an old desktop server or VM and installed Traveler  After the first email, this server was business critical
  • 4. Now everyone has one  Once word was out…..  You became very popular
  • 5. iOS Devices are for “work”….  Hence the executives desire to get them to work  But we all know the real reason…
  • 6. Security Options  None. Erm….Whiskey Tango Foxtrot?  SSL on Domino  SSL on IHS in front of Domino (new in 9)  Reverse Proxy  IBM Mobile Connect  Certificate authentication**  You can always go back to BES ;)
  • 7. Traveler is “free”  Only if you don’t secure it  How much did your org spend on BES?  Server, CALs, Devices, Support….  Why do you not treat your Traveler as you did you BES?  Spend money and do it right and secure it  It’ll still come out cheaper than your BES did
  • 8. A word about DNS and SSL  Whatever solution you choose to secure your Traveler server….  Make sure DNS and protocol is the same inside and out  my_traveler_server.mycomany.com  If you use SSL on the outside, you must use it on the inside too  That means you may use more than one solution  Outside LAN : IHS + SSL + Reverse Proxy  Inside LAN : IHS + SSL
  • 9. None – aka the default  As the great Paul Mooney once said:  “Port 80 on Traveler is *very* unwise”  Your passwords (and everything else) is going across the internet in clear text  But…..  it scales well - joke  Still, I would not do this on my servers. Ever.  Even the installer warns you this is a bad idea  Free  Until you are hacked
  • 10. SSL on Domino  Everything is secure if you did it right  Redirect all traffic from 80 to SSL (443) in the server doc, ports  Self Signed SSL can be used  But cause issues on some (all?) Androids  You can get around this by side loading or maybe the via the Google Play store now  Domino SSL scaling may cause issues  Domino still “surfaced” on the internet  Reasonably cheap
  • 11. SSL on IHS in front of Domino  New in 9.0, install IBM HTTP Server (IHS)  Installed as option with Domino, on same server as Domino  Windows only for now, needs 9.0 IF1 ○ PMR if you want other OSes to get this  Will handle SSL  Fixes Domino scaling with SSL  “Allows” Domino HTTP to do TLS  IHS now surface to the internet  Reasonably cheap
  • 12. Reverse Proxy  A proxy (like Websphere Edge Server, F5 or Apache) in the DMZ forwards traffic to Traveler in the LAN/DMZ  Can also be done with IHS, not sure about the licensing of that  Domino has no surface on the internet  Proxy can handle SSL  Can be cheap, or expensive
  • 13. IBM Mobile Connect  IBM’s “headless VPN” solution  Think of it like a very secure reverse proxy  Can be used for iNotes, Connections and Quickr too  Out of the box (mostly) support for Traveler  No messy http.conf or domino.conf files  Maybe relatively cheap based on current license you have
  • 14. IBM Mobile Connect Licensing  If you have Domino Enterprise Server licensing  Full PVU or CEO  NOT Express  You get the CAL for IMC as an entitlement  Will only need to license IMC PVUs  None enterprise  You’ll need clients and PVUs
  • 15. All the previous slides were server security  What about users?  Usually the weakest link  Options  Complex internet password  Internet Password Lockout  Certificate based authentication
  • 16. Password Security  Your weakest link if you install Traveler correctly  Complex passwords are good for you  Suck for your user  Password changes are difficult to do on a device  There is a possible solution…
  • 17. Go password-less  Certificate based authentication  Well, on iOS devices  Android is on the Traveler road map (PMR it)  Really a function of the Domino HTTP server and the device  This is much easier with an MDM  Pushing certificates is easier with a MDM  You have to get the cert on the device  Make sure users have device passwords!!!
  • 18. Conclusion  You may decide to use multiple methods  Domino + IHS + IMC + Certificates  Yes, it can get complex  Yes, it can be very, very secure  Almost BES like, but not quite  You may want to evaluate MDM’s before attempting a certificate roll out  Switching from non-SSL to SSL is “difficult”  A secure, HA Traveler platform can be expensive to implement  But hey, so was BES
  • 19. Q&A and links  http://blog.darrenduke.net  Mostly useful stuff, some rants  http://www.simplified-tech.com  No rants, Lisa won’t let me  https://twitter.com/darrenduke  Mostly rants, some useful stuff  http://geldreddotcom.files.wordpress.com/2013/05/choosing-a- mdm-presentation.pdf  choosing an MDM  I like DesktopCentral for the record  Never allow Anonymous access to the Domino Directory…..ever. Never.